The Cloud Cube

Adrius42 5,409 views 22 slides Mar 21, 2009
Slide 1
Slide 1 of 22
Slide 1
1
Slide 2
2
Slide 3
3
Slide 4
4
Slide 5
5
Slide 6
6
Slide 7
7
Slide 8
8
Slide 9
9
Slide 10
10
Slide 11
11
Slide 12
12
Slide 13
13
Slide 14
14
Slide 15
15
Slide 16
16
Slide 17
17
Slide 18
18
Slide 19
19
Slide 20
20
Slide 21
21
Slide 22
22

About This Presentation

The current thinking around Cloud Forms in the Jericho Forum, it is evolving as we better grasp the challenge of Collaborating Securely in the Clouds.


Slide Content

The Benefits of the Clouds or Avoiding The Cloud Trap! Adrius42 Recording some of the Jericho Forum thinking as it is Thunk !

Then decide to which type of Cloud you want to move ? F I R S T C L A S S I F Y Y O U R D A T A !!! Determine what rules MUST apply to it. Must it only exist in specific trust levels? For example can it leave Europe? Does it have to stay in Safe Harbours? Must it stay in Europe? We need a universal data classification model that is simple ( cf G8 TLP) We need a recognised trust level standard for all aspects of computing We need standardised meta data that signals to “cloud security” the data’s security needs

Then decide do you want to move to the Clouds

To Cloud or Not to Cloud? Clouds Traditional

Then decide what data you want to allow in the Clouds

With what degree of translucency

For all Clouds are not equal... Fully automated Data Redundancy Fully automated Disaster Recovery Fully automated Data Backup and Recovery Massively Scalable Fully automated System Redundancy Full on Clouds this way >>>>> <<<< Same old Traditional Approach Self owned Disk Storage Data Redundancy ...sometimes Warmish Back up Data Centre For Disaster Recovery Significant switching impact And testing costs Tapes sent by Truck Data Backup and Recovery variable risk Manual System Recovery

Then decide what level you want to operate in the Clouds

Cloud Layers Process Software Platform Infrastructure Outcome / Value A b s t r a c t I o n o c c u r s h e r e ! 1st 2nd 3rd Last! Orchestration Security and IdAM

Then decide to which form of Cloud you want to move

Cloud Forms Internal External

Cloud Forms Proprietary Open

Cloud Forms Proprietary Open Internal External

Cloud Forms Perimeterised Deperimeterised To get through here y ou need a Collaboration Oriented Architecture and the Jericho Forum Commandments

Cloud Forms Perimeterised Deperimeterised Proprietary Open Internal External

Cloud Forms Perimeterised Deperimeterised Proprietary Open Internal External We need inter cloud “IPI” standards... especially those that enable Collaboration . IPI=“Information Programming Interface” There has to be a better name!!!

Cloud Patterns Perimeterised Deperimeterised Proprietary Open Internal External Recognise some pathways between Clouds will be easier to enable than others!

Cloud Patterns Perimeterised Deperimeterised Proprietary Open Internal External

...and ”then” ensure the controls you require are available in the Clouds... ...Oops!!! You mean “Cloud Security Central” doesn’t exist?

Cloud Layers Process Software Platform Infrastructure Outcome / Value A b s t r a c t I o n o c c u r s h e r e ! 1st 2nd 3rd Last! Orchestration Security and IdAM Cloud Maturity Scale

We haven’t even identified all the needs yet. Bread Crumb Detector Bread Crumb Hoover Cloud Identity Services and their Providers What about Trust Levels?

Proposed Individual Trust Levels Trust Intent Impact Trust Level Authentication Physical Level Label Activity World equiv T0 Stay None Anonymous None - Unidentified T1 Self Insignificant Self Asserted None Pseudonym Assertion* T2 Proof Minor Document Verified Authenticated: Proof of Abode of Identity Name, Address, Age Electricity Bill T3 T2+ Ability Major Legally/ Financially Authenticate Credit Credit Card to Commit Verified Worthiness and / Pay Payment Method 1Pay* Ability to Pay Varied Single use Authenticate Credit a single Financially Worthiness and Single Cash transaction Verified Use Payment Method T4 T2+ Material Government Government Passport Gov Id Verified T5 Protect Catastrophic Military Grade Positive Vetting Security Lives Clearance *1Pay: Can be appended to any Trust Level